CVE-2021-46434: Medium severity emqx vulnerability
UNSUPPORTED WHEN ASSIGNED EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46434?
CVE-2021-46434 is classified as a security vulnerability that affects the EMQ X Dashboard due to username enumeration.
How does CVE-2021-46434 impact the EMQ X Dashboard?
CVE-2021-46434 allows an attacker to determine valid usernames through differing responses during the login process.
How can organizations mitigate CVE-2021-46434?
Organizations should implement rate limiting and uniform response messages for authentication attempts to mitigate CVE-2021-46434.
Is there a patch available for CVE-2021-46434?
As CVE-2021-46434 is marked as unsupported, there may not be an official patch available for this vulnerability.
Which versions of EMQ X are affected by CVE-2021-46434?
CVE-2021-46434 affects EMQ X Dashboard version 3.0.0 specifically.